Skip to content

Security: FIDES-ANIMA/protocol

Security

SECURITY.md

Security

Reporting

Report a suspected vulnerability in any FIDES-ANIMA repository privately to contact@fides-anima.org before opening a public issue. Include the repository, the commit or version, the exact steps or command, the observed and expected behaviour, and whether the problem affects enforcement (a call that is allowed when it is documented to be blocked or approved), evidence (a receipt, signature, or ledger check that passes when it should fail), or supply chain (install, publish, or dependency behaviour).

You will receive an acknowledgement. The project is solo-maintained; expect triage within days, not hours. If you receive no acknowledgement within seven days, open a public issue that says a private report was sent, without details.

Scope

  • Enforcement bypasses in FIDES-ANIMA/protocol are in scope when they contradict what docs/CAPABILITY_STATUS.md claims. The classifier is a documented heuristic; a pattern it does not match is a reportable gap, not a vulnerability, unless the README or capability matrix says it is covered.
  • Ledger verification in FIDES-ANIMA/protocol-attestation-ledger: any way to make validate.py or verify-signatures.py return success for a tree that GOVERNANCE.md or SCHEMA.md forbids, or to obtain admission authority without the pinned steward key, is in scope.
  • Secrets. Any secret key material, token, or credential found in a repository, artifact, or log is in scope regardless of how it got there.

Operator-disable of hooks and plugins is by design (Law 2) and is not a vulnerability.

What we will not do

We will not ask a reporter to adopt the protocol, file a declaration, or sign anything to have a report considered. We will credit reporters who want credit and say nothing about those who do not.

There aren't any published security advisories